Use case · Salesforce platform teams
Scheduled security scans for every Salesforce org.
A platform team owns more orgs than anyone can audit by hand. Vulkro Cloud scans each of them on a schedule you set, keeps every result, and opens on the short list of what to fix first.
Vulkro Cloud · Vulkro for Salesforce · VS Code extension
- 1VK-214Guest user reads Invoice__c.Bank_Account__cAttack pathCritical
- 2VK-188Integration user holds Modify All DataIdentityHigh
- 3VK-231Connected app allows all users, no IP rangeExposureHigh
- 4VK-097Session timeout above 2 hours on admin profileSettingsMedium
01The problem
Org access changes between yearly audits
Access in Salesforce drifts through everyday admin work, long after the last review signed it off.
Change outside code
A permission set, a sharing rule or a connected app is changed in Setup, not in a pull request. Nothing reviews it.
Sandboxes drift
Sandboxes and production stop matching, and a fix made in one never reaches the other.
Findings lists with no history
A findings list from each org, each run, with no memory of what was fixed or accepted last time.
Issues have no owner
An issue with no owner, no status and no history is an issue that comes back.
02How Vulkro handles it
What each part of Vulkro does
- Production, sandboxes and Experience Cloud orgs, scanned daily, weekly or monthly, in parallel and each in its own container
- One issue list per org with stable VK-nnn keys, closed on its own when a rescan no longer finds the issue
- Fix first, Attack Paths, Identity & Access, Exposure, Changes and History
- Alerts to Slack, Microsoft Teams, Jira (status read back), PagerDuty, Google Chat, Discord, email and webhooks
- Apex, LWC, Aura, Visualforce, Flows and metadata in the DX project, on your machine or in CI
- Live-org audits through your own sf CLI login, read-only (Pro)
- What a metadata change grants, and to whom, before it ships (Pro)
- The Vulkro Cloud issue list from the terminal, after one `vulkro-sf cloud connect`
- The finding underlined on the line that causes it
- How each Apex class runs: system or user mode, with or without sharing
- Explain and fix from the lightbulb
03The workflow
Steps from first scan to fix
- 01Vulkro Cloud
Connect your orgs
Add production, sandboxes and Experience Cloud orgs to your workspace. Scans read settings and metadata, never your records.
- 02Vulkro Cloud
Set the schedule
Daily, weekly or monthly per org, with a quiet window so no scan starts during a release.
- 03Vulkro Cloud
Work through Fix first
Open issues ranked by severity, each with the attack path behind it. Assign an owner and route it to Jira or chat.
- 04VS Code extension
Fix in the editor
The developer opens the class, sees the finding on the line and fixes it with the explanation in front of them.
- 05Vulkro Cloud
The rescan closes fixed issues
The next scheduled scan no longer finds the issue and marks it fixed. If it comes back, it is reopened.
04What you get
What you get
- Coverage
- Every live org on its own schedule, scanned in parallel.
- Change
- After two complete scans, Changes shows what is new, what was fixed and what came back.
- Priority
- Fix first: open issues by severity, with the path that makes each one matter.
- Accountability
- An accepted risk or false positive stays counted until a second person approves it.
- Access
- Roles from Owner to Auditor and Viewer, scoped per org, or roles of your own.
Questions
Common questions
- Does Vulkro Cloud read our customer records?
- No. Scans read settings and metadata. Each company gets its own workspace with its own database, storage and keys, and each scan runs in an isolated container.
- Can we try it today?
- Vulkro Cloud is available by invitation. Request access and we reply within two business days. Meanwhile Vulkro for Salesforce scans your DX project on your own machine, free.
- Does Vulkro Cloud change anything in our orgs?
- No. Vulkro reports and proposes fixes as Setup paths and metadata changes. It never deploys or applies a fix.
- Can we add our own policies?
- Yes. Write custom rules on users, permission sets, integrations, Health Check settings or Apex, and test them on the latest scan before they go live.